3 ms·
Well you don't really need to get the auth to interoperate per se; the only machine that is allowed to connect to the FastAPI backend is the machine running the
by eigenvalue 2y ago
Well you don't really need to get the auth to interoperate per se; the only machine that is allowed to connect to the FastAPI backend is the machine running the NextJS app, and it passes along the email address of the user making the request to the FastAPI backend.
And the user auth stuff in NextJS is incredibly easy using the standard Next-Auth flow: https://next-auth.js.org/ https://next-auth.js.org/
You basically just set up a new application in the Google Cloud console, enable the Google Plus API for the app, and create the OAuth keys, and that's about it. Just add the secret key and identifier to your .env file for the NextJS app and it "just works".
- daft_pink 2y agoSo essentially, you only let the server side rendering function, access the API and don’t secure it at all beyond that? You could essentially use a static JWT token that only that nexts cloud function knows?
- eigenvalue 2y agoYeah, I restrict it by the IP address, so the FastAPI backend can only receive connections from localhost or the one machine running the NextJS app. There are certainly lots of ways you could restrict it, such as using a password or key.